I making a Web App and Web API. I have done this in my web API
public void Post([FromBody] Expense expense)
{
string commandText = "INSERT INTO EXPENSE (Date, Description,Rate, BranchId) VALUES " +
" (@Date, @Description, @Rate, @BranchId)";
string connStr = System.Configuration.ConfigurationManager.ConnectionStrings["connectionString"].ConnectionString;
using (SqlConnection connection = new SqlConnection(connStr))
{
using (SqlCommand command = new SqlCommand(commandText, connection))
{
connection.Open();
command.CommandType = CommandType.Text;
command.Parameters.AddWithValue("@Date", (DateTime)expense.Date);
command.Parameters.AddWithValue("@Description", (string)expense.Description);
command.Parameters.AddWithValue("@Rate", (Decimal)expense.Rate);
command.Parameters.AddWithValue("@BranchId", (int)expense.BranchId);
int rowInserted = command.ExecuteNonQuery();
connection.Close();
}
}
}
When I send all parameters to my Web API from my web app then it works well but Rate and Branch Id are optional. If I don't send BranchId and Rate then it give me error "POST/ 405 (Method Not Allowed)". What can I do to make parameters optional. Input comes in json format.
ManageExpense() {
//object is to post data in JSON format to API
let object: any = {};
object.Date = this.Expense.Date;
object.Description = this.Expense.Description;
object.Rate = this.Expense.Rate;
object.BranchId = this.Expense.Branch.Id;
this.httpService.post('https://localhost:44373/api/add', object)
.then(res => {
console.debug(res);
});
return this.router.navigateToRoute("home");
}
Even on front end also I am getting error , if I am not sending all parameters
used to execute inline script because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-ThhI8UaSFEbbl6cISiZpnJ4Z44uNSq2tPKgyRTD3LyU='), or a nonce ('nonce-...') is required to enable inline execution. Note also that 'script-src' was not explicitly set, so 'default-src' is used as a fallback.